CVE-2025-58098 - Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

CVE-2025-58098 - Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

CVE ID : CVE-2025-58098 Published : Dec. 5, 2025, 2:15 p.m. | 46 minutes ago Description : Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd=

CVE Details

Published
Dec. 5, 2025
Affected Product: Apache

Source: Telegram CVE Monitor